Multiple Sensys network product Security Restriction Bypass Vulnerability (CVE-2014-2378)
Released on: 2014-09-05
Updated on:
Affected Systems:
Sensys Networks VSN240-F
Sensys Networks VSN240-T
Description:
Bugtraq id: 69641
CVE (CAN) ID: CVE-2014-2378
Sensys Networks is a vendor of wireless traffic detection and integrated traffic data systems and is headquartered in the United States.
Sensys Networks VSN240-F and VSN240-T traffic sensor 2.10.1 earlier versions, TrafficDOT 2.10.3 earlier versions did not verify the integrity of the download update, which allows remote attackers to exploit this vulnerability to execute arbitrary code through Trojans.
<* Source: Cesar Cerrudo (cesarc56@yahoo.com)
*>
Suggestion:
Vendor patch:
Sensys Networks
---------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.sensysnetworks.com/resources-by-category/
This article permanently updates the link address: